From nobody Mon Sep 28 08:47:41 2026 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 196893F54BF for ; Mon, 24 Aug 2026 11:35:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787571324; cv=none; b=qkifVjp4FC43qx8MaZLMOuKvfmKL1y0nSPhU3V+eGYnHAgXot5RBn9CjOQCF+lPBqDCJpmFK6kk6jF6iXyTJnVhRtq1oISchZe4mB6Kj95VOKf+z7BJOOjNq+CGn3lcFPM/m4kad+X0FYc2QntJsfYhzoYrEQD0hT9ZnYTMFDHc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787571324; c=relaxed/simple; bh=jN51nYw4hd9tMCSCZa/mgI1hQArmTZ9M6nj9ZQTMYjI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=BktjyH4n5lJgf61SgiFgzbwgIrV/Q1xu0fkr1bcG000I7yeKtDRWjNiMeyOSOTaIb4Wb7fmRuFiwTZIFZiTlN6KzAuwaRWUPzh9g+KXl8Z498wx0OKATRUSn435BKNbr9JADPaqH0aqp7LM3NBYes78QHAOqasBjPP1//IFTOWs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=KLMxVwnD; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="KLMxVwnD" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38f0f132f56so3159459a91.0 for ; Mon, 24 Aug 2026 04:35:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787571320; x=1788176120; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=xs4/hw8x1PBD+pLQSTNuCqi+GxQzrOw0Fm/12NJE7qo=; b=KLMxVwnDnUL0DlqBMa6lzF1HiFZyMZ7Y+rj1sy2B/h/pzVgu8BoXglIdd3JJ6dZk9N BA7gN0vvjA60p1+ICcuqPak8xze7yEK3YwRj5cNZzyMHhZXs10Vbp36CB2JEfuafbjmq DMD+SoxhrVDHCZ3I7laDvJyL5GCoboEaej8QA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787571320; x=1788176120; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xs4/hw8x1PBD+pLQSTNuCqi+GxQzrOw0Fm/12NJE7qo=; b=MWcHn1uCPF+s4WMMT7a8XPeE5GB0HQdU0EgB+I4IO83t4J1M87rgp1yqSn8r6kpLB2 G31+N6to/oZsNKTqg7xoxETc75LL9xRdiqP5pXu/yKabbJPVaBc00PHPhwWuPkhfzyor pn168b7G70Q4PPSAWQmb1UYmL0ONOaPqqZsflVnT8+dsc1WQcww/k3Tyxs3+iKQbwZsC Ugg+iR6sHXq/Lky6PoFbRtC2hFkUL/KE3zoIzE+96HsAI7J6VVfBOKoxfaVgfMml/YJv b2Atx76C+CB47H17gQLnJlG6RirqpJ8RGLjInIqNS6tu6d1jSJ9eDwUgfivrQdX4Uph3 X6kw== X-Forwarded-Encrypted: i=1; AHgh+Rpb0f+l2q4VlrSaNsIPLvXAnAnc3V67QPGnmlIWv7LkbTlrqdK/Gtne73QVijfejNbYUaQNcaTInRSG7+A=@vger.kernel.org X-Gm-Message-State: AFuF++nQOhdYdunvJsRY/uV1Q4HIrz7rpB3qr4sxKZ3Dzka5AfEmvfp5 NWPqkGr6ggsxj4IK+9xBNFVygY/HWrvkvxDBnzRQiqcVYPk/lxKPVOkCZM6iS+qfgqNFeM6+B7w Jx49Xxa4= X-Gm-Gg: AR+sD13zttYaX0cQ/85yiuuQjTjTK5yH5D6D8/UPPyHfcu/tlWVUiXAqzqJn7pHzMvb DSF76E75rgJCDZVTr9PhrvxxMrHwZvvlMzZTBZ/JGI7vbVOQX/X7zo2Cmb7LuIOJRJuk4W9g1ne CDwmk+3ggWwmEz77rrnnUWGuq+D5wtPKho7orke7k1wv8P6ZsJzcp06DRUenk1tvgCxYugCZo4c NFVGyUWnY93u0mnjZkP+1CDu4DZAMzMYu4bQZXtbuORtTBmAK6Wz/7YZD1ryNaDBJJMJyv/NW1/ e4JsxXijA1k3h6zWDKQaUkvMOf0hJthD1GD871Yd9hCuQFff720NzN4PpGRU+pVlMel4df0TPBZ k0FwVaiEcCIu0rtepKJ8IB1Xn1tdNxmNEheBZRgQoai9NqYF9vGqC2Rt/4Il+DXno9fZfK/E+X2 UDNkwf8ZjkCfcmDnYKXLgkJfSSF9ccezwC9ew2dxwvVG4776kxZWPgV7xqOxt5pQd6kvh55SXOc IGaxOlc0vH4eUx6GGgJar14HRvw0f9bJzcBzpoQLzlxNw8eFN9Cp9VKZD2ZihzFDIelKnsP4fvV EI60ok4TBztpyvnDbeabVxRtIklc1P9S1Vs7lkfWkuTlJEcbFylrQA== X-Received: by 2002:a17:90b:37c5:b0:38e:6d55:b1a6 with SMTP id 98e67ed59e1d1-395c4c35ac3mr23768088a91.3.1787571320129; Mon, 24 Aug 2026 04:35:20 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-395c911646dsm4771885a91.2.2026.08.24.04.35.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 04:35:19 -0700 (PDT) From: Jaeyoung Chung To: gregkh@linuxfoundation.org, linux-usb@vger.kernel.org Cc: brauner@kernel.org, jack@suse.cz, kees@kernel.org, linux-kernel@vger.kernel.org, mjguzik@gmail.com, viro@zeniv.linux.org.uk, eulgyukim@snu.ac.kr, jjy600901@snu.ac.kr Subject: [BUG] general protection fault in gadget_dev_ioctl Date: Mon, 24 Aug 2026 20:35:09 +0900 Message-ID: <20260824113510.1141236-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "general protection fault in gadget_dev_ioctl" on Linux v7.2. The issue was found by our own race fuzzer. We have not analyzed the root c= ause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. The following kernel config options are required to reproduce the issue: CONFIG_USB_SUPPORT=3Dy CONFIG_USB=3Dy CONFIG_USB_GADGET=3Dy CONFIG_USB_DUMMY_HCD=3Dy CONFIG_USB_GADGETFS=3Dy CONFIG_KASAN=3Dy We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/drivers/usb/gadget/legacy/inode.c b/drivers/usb/gadget/legacy/= inode.c index d87a8ab51510..b996abcae31a 100644 --- a/drivers/usb/gadget/legacy/inode.c +++ b/drivers/usb/gadget/legacy/inode.c @@ -1254,6 +1254,10 @@ static long gadget_dev_ioctl (struct file *fd, unsig= ned code, unsigned long valu struct usb_gadget *gadget =3D dev->gadget; long ret =3D -ENOTTY; =20 + if (!gadget && strncmp(current->comm, "syzrepro1", 9) =3D=3D 0) { + mdelay(100); + } + spin_lock_irq(&dev->lock); if (dev->state =3D=3D STATE_DEV_OPENED || dev->state =3D=3D STATE_DEV_UNBOUND) { @@ -1805,6 +1809,9 @@ dev_config (struct file *fd, const char __user *buf, = size_t len, loff_t *ptr) unsigned total; u32 tag; char *kbuf; + if (strncmp(current->comm, "syzrepro0", 9) =3D=3D 0) { + mdelay(60); + } =20 spin_lock_irq(&dev->lock); if (dev->state > STATE_DEV_OPENED) { diff --git a/fs/ioctl.c b/fs/ioctl.c index 1c152c2b1b67..090d2d03d91e 100644 --- a/fs/ioctl.c +++ b/fs/ioctl.c @@ -11,6 +11,7 @@ #include #include #include +#include #include #include #include @@ -48,6 +49,10 @@ static int vfs_ioctl(struct file *filp, unsigned int cmd= , unsigned long arg) if (!filp->f_op->unlocked_ioctl) goto out; =20 + if (strncmp(current->comm, "syzrepro", 8) =3D=3D 0) { + mdelay(5); + } + error =3D filp->f_op->unlocked_ioctl(filp, cmd, arg); if (error =3D=3D -ENOIOCTLCMD) error =3D -ENOTTY; @@ -588,6 +593,10 @@ SYSCALL_DEFINE3(ioctl, unsigned int, fd, unsigned int,= cmd, unsigned long, arg) if (fd_empty(f)) return -EBADF; =20 + if (strncmp(current->comm, "syzrepro", 8) =3D=3D 0) { + mdelay(5); + } + error =3D security_file_ioctl(fd_file(f), cmd, arg); if (error) return error; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #include #include #include #include #include #include #include /* tag(4) + full-speed config descriptor(9) + device descriptor(18) =3D 31 = */ static const unsigned char cfg_blob[31] =3D { /* tag =3D 0 */ 0x00, 0x00, 0x00, 0x00, /* struct usb_config_descriptor */ 0x09, /* bLength =3D USB_DT_CONFIG_SIZE */ 0x02, /* bDescriptorType =3D USB_DT_CONFIG */ 0x09, 0x00, /* wTotalLength =3D 9 */ 0x01, /* bNumInterfaces =3D 1 */ 0x01, /* bConfigurationValue=3D 1 (must be !=3D 0) */ 0x00, /* iConfiguration */ 0x80, /* bmAttributes: ATT_ONE set, ATT_WAKEUP clear */ 0x01, /* bMaxPower */ /* struct usb_device_descriptor */ 0x12, /* bLength =3D USB_DT_DEVICE_SIZE */ 0x01, /* bDescriptorType =3D USB_DT_DEVICE */ 0x00, 0x02, /* bcdUSB */ 0x00, 0x00, 0x00, 0x40, /* bMaxPacketSize0 */ 0x00, 0x00, /* idVendor */ 0x00, 0x00, /* idProduct */ 0x00, 0x00, /* bcdDevice */ 0x00, 0x00, 0x00, 0x01, /* bNumConfigurations =3D 1 */ }; static int ep0fd =3D -1; static volatile int t1_armed; static volatile int go; static void *thr_ioctl(void *arg) /* syzrepro1: the victim */ { long r; (void)arg; prctl(PR_SET_NAME, "syzrepro1", 0, 0, 0); while (!go) sched_yield(); t1_armed =3D 1; r =3D ioctl(ep0fd, 0x227c /* SG_GET_PACK_ID, value is irrelevant */, 0UL); printf("[T1] ioctl -> %ld (errno %d)\n", r, errno); fflush(stdout); return NULL; } static void *thr_write(void *arg) /* syzrepro0: triggers gadgetfs_bind */ { ssize_t n; (void)arg; prctl(PR_SET_NAME, "syzrepro0", 0, 0, 0); while (!go) sched_yield(); while (!t1_armed) sched_yield(); usleep(2000); n =3D write(ep0fd, cfg_blob, sizeof(cfg_blob)); printf("[T0] write -> %zd (errno %d)\n", n, errno); fflush(stdout); return NULL; } /* find the ep0 file: gadgetfs names it after the UDC (usually dummy_udc) */ static int find_chip(const char *dir, char *out, size_t outsz) { DIR *d; struct dirent *e; int found =3D 0; d =3D opendir(dir); if (!d) { printf("[!] opendir(%s) failed errno=3D%d\n", dir, errno); return -1; } while ((e =3D readdir(d)) !=3D NULL) { if (!strcmp(e->d_name, ".") || !strcmp(e->d_name, "..")) continue; snprintf(out, outsz, "%s", e->d_name); found =3D 1; if (!strcmp(e->d_name, "dummy_udc")) break; /* preferred */ } closedir(d); return found ? 0 : -1; } static const char *pick_dir(void) { static const char *cands[] =3D { "/gadget", "/tmp/gadget", "./gadget", "/root/gadget", NULL }; int i; for (i =3D 0; cands[i]; i++) { if (mkdir(cands[i], 0777) =3D=3D 0 || errno =3D=3D EEXIST) return cands[i]; printf("[!] mkdir(%s) failed errno=3D%d\n", cands[i], errno); } return NULL; } static int one_round(const char *dir, int iter) { char chip[256], path[512]; pthread_t t0, t1; int rc; if (mount(NULL, dir, "gadgetfs", 0, NULL) !=3D 0) { printf("[%d] mount(gadgetfs) failed errno=3D%d\n", iter, errno); return -1; } if (find_chip(dir, chip, sizeof(chip)) !=3D 0) { printf("[%d] no ep0 file under %s\n", iter, dir); umount2(dir, MNT_DETACH); return -1; } snprintf(path, sizeof(path), "%s/%s", dir, chip); ep0fd =3D open(path, O_RDWR); if (ep0fd < 0) { printf("[%d] open(%s) failed errno=3D%d\n", iter, path, errno); umount2(dir, MNT_DETACH); return -1; } printf("[%d] ep0=3D%s fd=3D%d -- racing\n", iter, path, ep0fd); fflush(stdout); t1_armed =3D 0; go =3D 0; rc =3D pthread_create(&t1, NULL, thr_ioctl, NULL); if (rc) { printf("[%d] pthread_create t1 rc=3D%d\n", iter, rc); close(ep0fd); umount2(dir, MNT_DETACH); return -1; } rc =3D pthread_create(&t0, NULL, thr_write, NULL); if (rc) { printf("[%d] pthread_create t0 rc=3D%d\n", iter, rc); go =3D 1; pthread_join(t1, NULL); close(ep0fd); umount2(dir, MNT_DETACH); return -1; } go =3D 1; pthread_join(t1, NULL); pthread_join(t0, NULL); close(ep0fd); ep0fd =3D -1; if (umount(dir) !=3D 0) { printf("[%d] umount failed errno=3D%d, detaching\n", iter, errno); umount2(dir, MNT_DETACH); } return 0; } int main(int argc, char **argv) { const char *dir; int iters =3D 20; int i; setvbuf(stdout, NULL, _IONBF, 0); /* argv: ; nthreads is fixed at 2 here */ if (argc > 2) { int v =3D atoi(argv[2]); if (v > 0) iters =3D v; } if (argc > 1) printf("[*] marker=3D%s iters=3D%d (2 racing threads: " "syzrepro0/syzrepro1)\n", argv[1], iters); dir =3D pick_dir(); if (!dir) { printf("[!] no usable mount point\n"); return 1; } printf("[*] mount point %s\n", dir); /* in case a previous run left it mounted */ umount2(dir, MNT_DETACH); for (i =3D 0; i < iters; i++) { if (one_round(dir, i) !=3D 0) usleep(100000); } printf("[*] done\n"); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Oops: general protection fault, probably for non-canonical address 0xdffffc= 0000000005: 0000 [#1] SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000028-0x000000000000002f] CPU: 3 UID: 0 PID: 401 Comm: syzrepro1 Not tainted 7.2.0-dirty #2 PREEMPT=20 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 RIP: 0010:gadget_dev_ioctl+0xf0/0x240 drivers/usb/gadget/legacy/inode.c:1265 Code: 41 8b 06 49 c7 c6 e7 ff ff ff 83 c8 04 83 f8 05 0f 84 e7 00 00 00 89 = 6c 24 0c 4c 89 6c 24 10 49 8d 6f 28 49 89 ed 49 c1 ed 03 <43> 80 7c 25 00 0= 0 74 08 48 89 ef e8 40 3c 79 fd 4c 8b 65 00 49 83 RSP: 0018:ffff88810a27fe58 EFLAGS: 00010006 RAX: 0000000000000006 RBX: ffff88810179e800 RCX: 0000000000000001 RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffff88810a27fe3c RBP: 0000000000000028 R08: ffff88810a27fe3f R09: 1ffff1102144ffc7 R10: dffffc0000000000 R11: ffffed102144ffc8 R12: dffffc0000000000 R13: 0000000000000005 R14: ffffffffffffffe7 R15: 0000000000000000 FS: 000077fc4fcbd6c0(0000) GS:ffff88816488a000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000077fc4fdaf010 CR3: 000000010c042000 CR4: 00000000000006f0 Call Trace: vfs_ioctl fs/ioctl.c:56 [inline] __do_sys_ioctl fs/ioctl.c:606 [inline] __se_sys_ioctl+0x173/0x1c0 fs/ioctl.c:588 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x77fc4fdbed6b Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 = 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 f= f ff 77 1c 48 8b 44 24 18 64 48 2b 04 25 28 00 00 RSP: 002b:000077fc4fcbce70 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 000077fc4fcbd6c0 RCX: 000077fc4fdbed6b RDX: 0000000000000000 RSI: 000000000000227c RDI: 0000000000000003 RBP: 0000000000000000 R08: 0000000000000000 R09: 00007ffcdf85dd27 R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff80 R13: 0000000000000016 R14: 00007ffcdf85dc30 R15: 000077fc4f4bd000 Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:gadget_dev_ioctl+0xf0/0x240 drivers/usb/gadget/legacy/inode.c:1265 Code: 41 8b 06 49 c7 c6 e7 ff ff ff 83 c8 04 83 f8 05 0f 84 e7 00 00 00 89 = 6c 24 0c 4c 89 6c 24 10 49 8d 6f 28 49 89 ed 49 c1 ed 03 <43> 80 7c 25 00 0= 0 74 08 48 89 ef e8 40 3c 79 fd 4c 8b 65 00 49 83 RSP: 0018:ffff88810a27fe58 EFLAGS: 00010006 RAX: 0000000000000006 RBX: ffff88810179e800 RCX: 0000000000000001 RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffff88810a27fe3c RBP: 0000000000000028 R08: ffff88810a27fe3f R09: 1ffff1102144ffc7 R10: dffffc0000000000 R11: ffffed102144ffc8 R12: dffffc0000000000 R13: 0000000000000005 R14: ffffffffffffffe7 R15: 0000000000000000 FS: 000077fc4fcbd6c0(0000) GS:ffff88816488a000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000077fc4fdaf010 CR3: 000000010c042000 CR4: 00000000000006f0 ---------------- Code disassembly (best guess): 0: 41 8b 06 mov (%r14),%eax 3: 49 c7 c6 e7 ff ff ff mov $0xffffffffffffffe7,%r14 a: 83 c8 04 or $0x4,%eax d: 83 f8 05 cmp $0x5,%eax 10: 0f 84 e7 00 00 00 je 0xfd 16: 89 6c 24 0c mov %ebp,0xc(%rsp) 1a: 4c 89 6c 24 10 mov %r13,0x10(%rsp) 1f: 49 8d 6f 28 lea 0x28(%r15),%rbp 23: 49 89 ed mov %rbp,%r13 26: 49 c1 ed 03 shr $0x3,%r13 * 2a: 43 80 7c 25 00 00 cmpb $0x0,0x0(%r13,%r12,1) <-- trapping instr= uction 30: 74 08 je 0x3a 32: 48 89 ef mov %rbp,%rdi 35: e8 40 3c 79 fd callq 0xfd793c7a 3a: 4c 8b 65 00 mov 0x0(%rbp),%r12 3e: 49 rex.WB 3f: 83 .byte 0x83 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D